THREAT AWARE DATA PROTECTION
A method and system for threat aware data protection. Threat awareness intelligence, directed to preventing information or cyber security issues, are becoming a critical requirement for data protection (or backup) services. Accordingly, a centralized policy framework is proposed through which threat evaluations may be performed synchronously, as well as asynchronously, with data backup operations to ensure the ingestion of threat-free data into backup storage.
1 . A method for threat awareness data protection, comprising:
instructing a threat agent to perform a threat evaluation of an asset residing on an asset source;
receiving, from the threat agent and following the threat evaluation, a threat evaluation report comprising an incident;
analyzing the incident to derive an actionable response; and
applying the actionable response.
2 . The method of claim 1 , wherein performance of the threat evaluation is based on a protection policy for the asset.
3 . The method of claim 2 , wherein the protection policy comprises a collection of rules and preferences directed to protecting asset data and metadata against cyber security threats.
4 . The method of claim 3 , wherein the collection of rules and preferences comprises at least one scan run optimization of a group of scan run optimizations consisting of specifying a maximum time allowed to perform a scan run, and excluding unmodified elements of the asset data and metadata from the scan run.
5 . The method of claim 1 , wherein the incident captures a detection of at least one of a group of cyber security threats consisting of malware infections, distributed denial of service diversions, unauthorized accesses, insider breaches, unauthorized privilege escalations, destructive attacks, and advanced persistent threat attacks.
6 . The method of claim 1 , wherein the actionable response comprises quarantining infected asset data and metadata.
7 . The method of claim 6 , wherein the actionable response further comprises storing non-infected asset data and metadata onto a backup target as an asset backup associated with the asset.
8 . The method of claim 1 , wherein the threat agent is instructed to perform the threat evaluation of the asset synchronously with a backup operation targeting the asset.
9 . The method of claim 1 , further comprising:
making a determination that post-backup checking is enabled;
based on the determination:
instructing the threat agent to perform a second threat evaluation of an asset backup stored on a backup target;
receiving, from the threat agent and following the second threat evaluation, a second threat evaluation report comprising a second incident;
analyzing the second incident to derive a second actionable response; and
applying the second actionable response.
10 . The method of claim 1 , wherein the asset backup comprises a copy of threat-free data and metadata pertaining to the asset.
11 . A non-transitory computer readable medium (CRM) comprising computer readable program code, which when executed by a computer processor, enables the computer processor to perform a method for threat awareness data protection, the method comprising:
instructing a threat agent to perform a threat evaluation of an asset residing on an asset source;
receiving, from the threat agent and following the threat evaluation, a threat evaluation report comprising an incident;
analyzing the incident to derive an actionable response; and
applying the actionable response.
12 . The non-transitory CRM of claim 11 , wherein performance of the threat evaluation is based on a protection policy for the asset.
13 . The non-transitory CRM of claim 12 , wherein the protection policy comprises a collection of rules and preferences directed to protecting asset data and metadata against cyber security threats.
14 . The non-transitory CRM of claim 13 , wherein the collection of rules and preferences comprises at least one scan run optimization of a group of scan run optimizations consisting of specifying a maximum time allowed to perform a scan run, and excluding unmodified elements of the asset data and metadata from the scan run.
15 . The non-transitory CRM of claim 11 , wherein the incident captures a detection of at least one of a group of cyber security threats consisting of malware infections, distributed denial of service diversions, unauthorized accesses, insider breaches, unauthorized privilege escalations, destructive attacks, and advanced persistent threat attacks.
16 . The non-transitory CRM of claim 11 , wherein the actionable response comprises quarantining infected asset data and metadata.
17 . The non-transitory CRM of claim 16 , wherein the actionable response further comprises storing non-infected asset data and metadata onto a backup target as an asset backup associated with the asset.
18 . The non-transitory CRM of claim 11 , wherein the threat agent is instructed to perform the threat evaluation of the asset synchronously with a backup operation targeting the asset.
19 . The non-transitory CRM of claim 11 , the method further comprising:
making a determination that post-backup checking is enabled;
based on the determination:
instructing the threat agent to perform a second threat evaluation of an asset backup stored on a backup target;
receiving, from the threat agent and following the second threat evaluation, a second threat evaluation report comprising a second incident;
analyzing the second incident to derive a second actionable response; and
applying the second actionable response.
20 . The non-transitory CRM of claim 11 , wherein the asset backup comprises a copy of threat-free data and metadata pertaining to the asset.